You Passed Security+. Now What? The Case for Cloud Security (and When to Ignore It)

·

·

Full length of IT consultant using laptop while monitoring servers in datacenter

Short answer: if you already work in IT, the strongest next move after Security+ is usually cloud security — on the platform your employer already runs. Security+ taught you the vocabulary. Cloud security is where that vocabulary turns into configurations, identities, and logs you can actually point to. Below: why, when it’s the wrong call, which certification fits your background, and three labs that prove the skill better than any exam score.

First, congratulations. Passing Security+ is real work, and it does something concrete for you: it gets your resume past the keyword filter for security roles.

What it doesn’t do is tell you where to go next. And that’s where most people stall — staring at a list of acronyms (CySA+, CCSP, AZ-500, SCS-C03, CISSP someday) and wondering which one is the “right” one. So let’s answer what to do after Security+ the way a security professional would: start with what you already have, then pick the move with the best return on it.

Why Cloud Security Is the Strongest Next Move for Most IT Pros

The controls moved, and you already work where they went

A decade ago, a lot of security lived in a physical perimeter: firewalls at the edge, a DMZ, a VPN concentrator. In most US organizations today, a large share of the controls that matter live in configuration: who can assume which role, which storage account allows anonymous reads, which network security group has port 3389 open to the internet, which logs are actually being collected.

If you’ve administered Entra ID, built VNets, written Terraform, or cleaned up an over-permissioned service account, you’ve already been doing security work. You just haven’t been calling it that — and neither has your resume.

The demand data points the same way

This isn’t a hunch. In the ISC2 2025 Cybersecurity Workforce Study, hiring managers named cloud security as the top technical skill they look for when hiring (29%), ahead of AI (27%) and security engineering (24%). Across all respondents whose teams had at least one skills need, 36% cited cloud computing security — second only to AI at 41%, and up from the 2024 study.

The same study found that 24% of respondents linked their skills shortages to misconfigured systems. That’s worth sitting with for a second: the most common cloud failure isn’t an exotic zero-day. It’s a setting someone didn’t understand. People who have spent years configuring infrastructure are unusually well positioned to fix that.

For the broader market: the U.S. Bureau of Labor Statistics projects employment of information security analysts to grow 21% from 2025 to 2035, with about 14,100 openings per year on average, and reports a median annual wage of $129,180 as of May 2025. That median covers the whole occupation, experienced analysts included — it is not what a first security role pays, and anyone treating it that way is misreading it.

When Cloud Security Is Not Your Next Step

We don’t sell a certification, so we have no reason to push you toward one. Cloud security is the right default for most infrastructure people — not for everyone. Consider a different direction if:

  • You want to work in a SOC and your cloud exposure is close to zero. If your background is help desk or desktop support, a detection-and-response track may be the shorter bridge. We break that route down in the help desk to SOC analyst path.
  • Your employer is almost entirely on-prem and staying that way. Skills you can practice at work compound faster than skills you can only practice in a personal lab. Security+ plus deeper network or endpoint security work may pay off sooner.
  • You’re drawn to risk, audit, and policy more than configuration. That’s a GRC path, and it rewards different evidence than cloud labs do.
  • You’re already getting security interviews and losing at the technical round. A second certification won’t fix that. The bottleneck is how you explain your decisions.

If none of those describes you, keep reading.

What Security+ Already Gave You in the Cloud

Your Security+ study wasn’t wasted time on the way to “real” cloud work. Almost every domain maps directly onto a cloud control you’ll configure:

What you learned for Security+What it becomes in the cloud
RBAC, MFA, least privilegeIAM roles and policies, Entra ID roles, Conditional Access — identity is the primary control plane
Firewalls, subnets, segmentationVPCs and VNets, security groups and NSGs, private endpoints
Encryption at rest and in transitKey management (AWS KMS, Azure Key Vault), customer-managed keys, TLS enforcement on storage and databases
Logging and monitoringCloudTrail, Azure Activity and sign-in logs, centralized log retention
Incident response processIsolating a compromised instance, revoking sessions, rotating exposed keys

The concepts transfer. What changes is the blast radius: one mistaken policy can expose every resource in an account at once. That’s precisely why employers want people who understand both the concept and the console.

What to Do After Security+: A Roadmap Calibrated to What You Already Run

Generic roadmaps assume you’ve never touched a cloud console. You probably have. Adjust accordingly.

Step 1: Pick one platform — the one your employer runs

Don’t try to learn AWS, Azure, and Google Cloud at the same time. Pick the one you can touch at work, because that’s where you’ll get real reps and where a new skill turns into a visible contribution fastest.

  • Azure / Microsoft shops: If you already administer Microsoft 365 or Entra ID, AZ-900 (Azure Fundamentals) is mostly review. Consider going straight to AZ-104 (Azure Administrator) — or directly to the security certification below if you already manage Azure resources day to day.
  • AWS shops: AWS Certified Cloud Practitioner is optional for someone with infrastructure experience. AWS Certified Solutions Architect – Associate usually teaches you more of what you’ll actually need: networking, IAM, storage, and how the services fit together.

The goal of this step isn’t a badge. It’s being able to explain how compute, storage, networking, and identity actually work on that platform — because you can’t secure what you can’t describe.

Step 2: Choose your cloud security certification

Once the platform fundamentals are solid, pick the credential that matches where you want to work.

Vendor-specific (strongest signal for hands-on roles):

  • AWS Certified Security – Specialty (SCS-C03): AWS overhauled this exam in December 2025. It covers identity, detection, incident response, infrastructure security, data protection, and governance on AWS. It’s an advanced exam — plan on real hands-on time with AWS before sitting it, not just videos.
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500): Implementing identity and access controls, network security, compute and data protection, and security operations in Azure. A natural fit if your day job already lives in Microsoft’s ecosystem.
  • Google Professional Cloud Security Engineer: The equivalent for Google Cloud shops.

Vendor-neutral (broader, more strategic):

  • CCSP (Certified Cloud Security Professional, ISC2): A well-recognized, architecture-level credential. Be realistic about the experience requirement: ISC2 asks for five years of cumulative full-time IT experience, three of them in cybersecurity and one in at least one CCSP domain. A relevant degree can waive one year, and an active CISSP covers the whole requirement. If you’re short, you can pass the exam and become an Associate of ISC2 while you earn the remaining experience — but this is usually a later move, not the one right after Security+.
  • CompTIA Cloud+: A broad, vendor-neutral view of cloud infrastructure operations. Useful if you want structure across platforms; it carries less security signal than the options above.

A rule of thumb for the fear of buying the wrong certification: if a job posting you actually want names a specific platform, the vendor certification for that platform beats a vendor-neutral one. When postings are mixed, the platform your current employer runs wins, because you can back the credential with work experience.

Step 3: Build three labs that prove the skill

Certifications show you can recognize the right answer. Labs show you can build it. Hiring managers can’t see your exam score in an interview, but they can ask you to walk through something you built.

Before you start: set a budget alert. Create a billing budget with an email alert at a small threshold on day one. Cloud labs are cheap until someone forgets to shut something down — and “I controlled cost and blast radius from the start” is itself a security talking point.

Lab 1 — Lock down a storage bucket, then prove it’s locked. On AWS, create an S3 bucket and turn on Block Public Access at the account level. Note that S3 has encrypted new objects by default since January 2023, so “enable encryption” isn’t the interesting part anymore — configure SSE-KMS with a customer-managed key and write a key policy that limits who can decrypt. Then try to read an object from a second IAM identity that shouldn’t have access, and find that denied request in your logs. On Azure, the equivalent is disabling anonymous blob access on the storage account, using a customer-managed key in Key Vault, and sending diagnostic logs to a Log Analytics workspace.

Lab 2 — Build an identity structure an auditor would sign off on. On AWS, set up AWS Organizations with IAM Identity Center and permission sets instead of long-lived IAM user access keys, require MFA, and add a service control policy that prevents anyone from disabling CloudTrail. On Azure, use management groups, require MFA for administrative roles through Conditional Access, and use Privileged Identity Management for just-in-time elevation. The artifact to capture: a one-page diagram of who can do what, and why.

Lab 3 — Turn a suspicious event into an alert someone actually receives. On AWS, enable GuardDuty (a managed threat-detection service — not a SIEM), create an EventBridge rule that routes findings to an SNS topic, subscribe your email, and use GuardDuty’s sample findings to test the pipeline end to end. On Azure, onboard Microsoft Sentinel (an actual cloud-native SIEM), connect Entra ID sign-in logs, write an analytics rule for a suspicious sign-in pattern, and attach an automation rule that notifies you. Watch data ingestion costs here.

For each lab, write down three things: what you built, which threat it addresses, and the evidence that it works. That turns a weekend project into a portfolio piece — we cover the format in how to document your cybersecurity labs, and there’s more on what hiring managers actually look for in these cybersecurity portfolio examples.

How a Security Professional Thinks About a Cloud Account

Tools and certifications change. The reasoning underneath them doesn’t. At Blue Team Academy we teach that reasoning as the Threat & Control Method — Inventory → Threats → Controls → Scale — and it maps cleanly onto a cloud environment:

  • Inventory: Which accounts, subscriptions, identities, and data stores exist? Which ones are critical? What’s already protecting them? Most cloud incidents start with something nobody knew was there.
  • Threats: What can realistically go wrong — a leaked access key, an over-permissioned role, a public bucket, a compromised admin session — and which of those matters most for this environment?
  • Controls: Which gaps close with which controls, in what order, and at what cost? This is where the three labs above stop being exercises and become decisions.
  • Scale: Can you apply the same reasoning to the next account, the next platform, the next acquisition — without starting over?

The labs teach you how to configure the controls. The method teaches you which ones to configure first, and how to defend that choice to someone who controls the budget. That second skill is what separates a certified candidate from a hired one.

The Bottom Line

Security+ opened the door. Cloud security is where most IT professionals get the best return on walking through it — because it builds on work you’re already doing instead of asking you to start over.

Cybersecurity is not rocket science. Pick one platform, earn the certification that matches the jobs you actually want, build three labs you can explain, and let your infrastructure experience do the heavy lifting.

If you’re still weighing whether Security+ itself was worth it for someone with your background, we took that question apart in is Security+ worth it with 10 years of IT experience. And if you’re comparing credentials beyond cloud, see our guide to blue team certifications for IT professionals. For the bigger picture of where each path leads, start with the blue team career path for IT professionals.

Want the decision process, not just the checklist? Our program turns the infrastructure you already run into a security plan you can defend — inventory, threats, controls, and how to prioritize them in a real environment.

Prefer it in smaller pieces? The Keep IT Safe newsletter breaks down one practical defensive decision each week, written for people still working full-time in IT. Sign up for Keep IT Safe.

Are you prepping for a cloud security certification right now, or leaning toward SOC or GRC instead? Tell us in the comments which platform your team runs — it changes the answer.